Unauthenticated SQL Injection in SendPress Newsletters by SendPress
CVE-2026-39795

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 October 2026

What is CVE-2026-39795?

The SendPress Newsletters plugin for WordPress is vulnerable to an unauthenticated SQL Injection attack in versions up to and including 1.26.1.20. This vulnerability allows attackers to execute arbitrary SQL queries in the database without authentication, potentially leading to unauthorized access to sensitive data and impacting the integrity of the site's database. This issue highlights the importance of securing plugins and keeping them updated to safeguard against potential exploitation.

Affected Version(s)

SendPress Newsletters <= 1.26.1.20

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aydan Arabadzha | Patchstack Bug Bounty Program
.